CVE-2022-28965: Medium severity avast premium security vulnerability
Multiple DLL hijacking vulnerabilities via the components instup.exe and wscproxy.exe in Avast Premium Security before v21.11.2500 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted DLL file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-28965?
CVE-2022-28965 is a vulnerability that allows attackers to execute arbitrary code or cause a Denial of Service (DoS) in Avast Premium Security before v21.11.2500.
How can an attacker exploit CVE-2022-28965?
An attacker can exploit CVE-2022-28965 by using a crafted DLL file to hijack the components instup.exe and wsc_proxy.exe in Avast Premium Security.
What is the severity of CVE-2022-28965?
CVE-2022-28965 has a severity rating of 6.5 (medium).
Which software versions are affected by CVE-2022-28965?
Avast Premium Security versions before v21.11.2500 are affected by CVE-2022-28965.
Is there a fix available for CVE-2022-28965?
Yes, updating Avast Premium Security to version 21.11.2500 or later fixes CVE-2022-28965.